We back the builders securing what AI makes possible.
We're operators first. Our partners have spent careers inside security teams, scaling companies through this industry's hardest problems. When we back a founder, we bring pattern recognition from the practitioner side — not just capital.

No Results Found
No blog posts match your query, please try a different query.
Why We Invested in Empirical: Building Global and Local AI Models for Cybersecurity
Empirical Security is building domain-specific AI models for cybersecurity, founded on the belief that the next generation of security is not a faster scanner or a better dashboard but a security intelligence layer combining global threat intelligence with local, customer-specific environment context. The platform operates through two concentric layers: a Global AI Model, a continuously updating probabilistic scoring model trained on years of curated, globally-pooled data with scores recomputing daily, and per-tenant Local Models, custom enterprise-specific cybersecurity domain models trained on each customer's own telemetry, assets, and controls, which constitute the company's real moat. The first applied use case is exploitation prioritization, answering not just what is vulnerable but what is exploitable in a specific environment right now, extending beyond CVE-based scoring into cloud misconfigurations and application security findings. The founding team invented risk-based vulnerability management and EPSS itself: CTO Michael Roytman is an original EPSS author, Chief Data Scientist Jay Jacobs co-chairs the EPSS Special Interest Group at FIRST, and Ed Bellis co-founded Kenna Security, serving as CTO through Cisco's 2021 acquisition after six years as CISO of Orbitz. EPSS is now integrated into over 120 security platforms and was explicitly endorsed by Anthropic in its April 2026 guidance for AI-accelerated vulnerability discovery, the first time a major LLM provider has backed a purpose-built cybersecurity prioritization model. Brightmind Partners is leading Empirical's $25 million Series A alongside Costanoa Ventures, Hyde Park Angels, and angel investors from across the security ecosystem, bringing total funding to $37 million.
Why We Invested in Empirical: Building Global and Local AI Models for Cybersecurity
Empirical Security is building domain-specific AI models for cybersecurity, founded on the belief that the next generation of security is not a faster scanner or a better dashboard but a security intelligence layer combining global threat intelligence with local, customer-specific environment context. The platform operates through two concentric layers: a Global AI Model, a continuously updating probabilistic scoring model trained on years of curated, globally-pooled data with scores recomputing daily, and per-tenant Local Models, custom enterprise-specific cybersecurity domain models trained on each customer's own telemetry, assets, and controls, which constitute the company's real moat. The first applied use case is exploitation prioritization, answering not just what is vulnerable but what is exploitable in a specific environment right now, extending beyond CVE-based scoring into cloud misconfigurations and application security findings. The founding team invented risk-based vulnerability management and EPSS itself: CTO Michael Roytman is an original EPSS author, Chief Data Scientist Jay Jacobs co-chairs the EPSS Special Interest Group at FIRST, and Ed Bellis co-founded Kenna Security, serving as CTO through Cisco's 2021 acquisition after six years as CISO of Orbitz. EPSS is now integrated into over 120 security platforms and was explicitly endorsed by Anthropic in its April 2026 guidance for AI-accelerated vulnerability discovery, the first time a major LLM provider has backed a purpose-built cybersecurity prioritization model. Brightmind Partners is leading Empirical's $25 million Series A alongside Costanoa Ventures, Hyde Park Angels, and angel investors from across the security ecosystem, bringing total funding to $37 million.
Pi: Building Zero Recurrence Code Security for the AI CodeGen Era
Pi Security is defining a new category, Zero Recurrence Code Security, built on the premise that the industry no longer has a vulnerability discovery problem but a vulnerability recurrence problem. Rather than generating more findings, Pi learns how an organization builds, breaks, fixes, and secures software, then turns that institutional security knowledge into preventative guardrails enforced across the software development lifecycle at design time, IDE time, and pull request time. The platform ingests context from prior incidents, tickets, pull requests, repositories, architecture decisions, and developer workflows to drive root cause analysis, variant discovery, contextual remediation, and ownership mapping, becoming a living security intelligence layer for developers, AI coding agents, and security teams. Founded by Guy Arazi, an offensive security operator and former CISO with roots at Palo Alto Networks and Microsoft, and Yonatan Ramon, who built safety-critical systems at Tesla, Pi raised a $35 million Series A alongside Third Point Ventures and angels including George Kurtz, Yevgeny Dibrov, and Nadir Izrael. Brightmind led Pi's Seed round in early 2025 and is continuing its support through the Series A.
Pi: Building Zero Recurrence Code Security for the AI CodeGen Era
Pi Security is defining a new category, Zero Recurrence Code Security, built on the premise that the industry no longer has a vulnerability discovery problem but a vulnerability recurrence problem. Rather than generating more findings, Pi learns how an organization builds, breaks, fixes, and secures software, then turns that institutional security knowledge into preventative guardrails enforced across the software development lifecycle at design time, IDE time, and pull request time. The platform ingests context from prior incidents, tickets, pull requests, repositories, architecture decisions, and developer workflows to drive root cause analysis, variant discovery, contextual remediation, and ownership mapping, becoming a living security intelligence layer for developers, AI coding agents, and security teams. Founded by Guy Arazi, an offensive security operator and former CISO with roots at Palo Alto Networks and Microsoft, and Yonatan Ramon, who built safety-critical systems at Tesla, Pi raised a $35 million Series A alongside Third Point Ventures and angels including George Kurtz, Yevgeny Dibrov, and Nadir Izrael. Brightmind led Pi's Seed round in early 2025 and is continuing its support through the Series A.
Aryon: Building the Proactive Cloud Security Policy Enforcement Platform
Brightmind invested in Aryon, founded by Ron Arbel, Ariel Litmanovich, and Yair Ladizhensky, with the founders' firsthand experience securing complex cloud control planes on Project Nimbus as members of Matzov, the IDF's elite cybersecurity unit, serving as the driving force behind a proactive approach to policy enforcement. Traditional cloud security has been reactive and fragmented, catching misconfigurations only after they reach production and consistently failing enterprises due to native enforcement tools that are hard to configure, risky to enforce, brittle in production, and easily bypassed. Aryon's proactive, preventative platform enforces policy before misconfigurations ever ship, embedding safe enforcement directly into the cloud control plane to ensure context-aware governance that holds across Azure, AWS, and GCP and extends toward AI, SaaS, M365, identity, and data security. With AI-generated code and offensive AI introducing vulnerabilities at machine speed while patching and remediation still operate at human speed, Brightmind sees Aryon as the foundational layer for proactive cloud policy enforcement while also reducing operational friction for the IT and platform teams responsible for governance at scale.
Aryon: Building the Proactive Cloud Security Policy Enforcement Platform
Brightmind invested in Aryon, founded by Ron Arbel, Ariel Litmanovich, and Yair Ladizhensky, with the founders' firsthand experience securing complex cloud control planes on Project Nimbus as members of Matzov, the IDF's elite cybersecurity unit, serving as the driving force behind a proactive approach to policy enforcement. Traditional cloud security has been reactive and fragmented, catching misconfigurations only after they reach production and consistently failing enterprises due to native enforcement tools that are hard to configure, risky to enforce, brittle in production, and easily bypassed. Aryon's proactive, preventative platform enforces policy before misconfigurations ever ship, embedding safe enforcement directly into the cloud control plane to ensure context-aware governance that holds across Azure, AWS, and GCP and extends toward AI, SaaS, M365, identity, and data security. With AI-generated code and offensive AI introducing vulnerabilities at machine speed while patching and remediation still operate at human speed, Brightmind sees Aryon as the foundational layer for proactive cloud policy enforcement while also reducing operational friction for the IT and platform teams responsible for governance at scale.
Artemis: Reimagining Security Operations for the AI-Era
Brightmind Partners announces their investment in Artemis, a new security operations platform founded by Shachar Hirshberg and Dan Shiebler (former leaders at AWS and Abnormal Security) that aims to reimagine SIEM for the AI era. The company introduces "adaptive protection," an approach that automates detection, investigation, and response by embedding deep enterprise context into an autonomous detection lifecycle, eliminating false positives and evaluating threats as complete attack stories. Unlike traditional SIEMs built on centralized data ingest and retention economics, Artemis offers architectural flexibility that works across multiple SIEMs, datastores, or its own storage, avoiding vendor lock-in. Brightmind praises the team's rapid execution—building in six months what the SIEM space has attempted for over a decade—along with their strong customer-obsessed culture.
Artemis: Reimagining Security Operations for the AI-Era
Brightmind Partners announces their investment in Artemis, a new security operations platform founded by Shachar Hirshberg and Dan Shiebler (former leaders at AWS and Abnormal Security) that aims to reimagine SIEM for the AI era. The company introduces "adaptive protection," an approach that automates detection, investigation, and response by embedding deep enterprise context into an autonomous detection lifecycle, eliminating false positives and evaluating threats as complete attack stories. Unlike traditional SIEMs built on centralized data ingest and retention economics, Artemis offers architectural flexibility that works across multiple SIEMs, datastores, or its own storage, avoiding vendor lock-in. Brightmind praises the team's rapid execution—building in six months what the SIEM space has attempted for over a decade—along with their strong customer-obsessed culture.
What everyone seems to be overlooking with Mythos and Project Glasswing
Stephen argues that while Mythos (an AI security model) giving 50 companies a 90-day head start to find vulnerabilities sounds promising, it's largely illusory — enterprises are already drowning in unpatched critical vulnerabilities and the remediation pipeline is far too slow and contentious to meaningfully close the gap in time. On day 91, when Mythos is broadly released, whatever defensive advantage was gained evaporates and attackers gain the same powerful exploit-generation capability. He recommends CISOs restructure their security orgs entirely — retiring traditional scanning teams in favor of one massive remediation-focused team, letting AI handle identification while humans focus solely on fixing. His deeper fear is that these capabilities will trickle into small, offline, guardrail-free local models, democratizing exploit generation in a way that creates systemic risk far beyond what any centralized tool with access controls can contain.
What everyone seems to be overlooking with Mythos and Project Glasswing
Stephen argues that while Mythos (an AI security model) giving 50 companies a 90-day head start to find vulnerabilities sounds promising, it's largely illusory — enterprises are already drowning in unpatched critical vulnerabilities and the remediation pipeline is far too slow and contentious to meaningfully close the gap in time. On day 91, when Mythos is broadly released, whatever defensive advantage was gained evaporates and attackers gain the same powerful exploit-generation capability. He recommends CISOs restructure their security orgs entirely — retiring traditional scanning teams in favor of one massive remediation-focused team, letting AI handle identification while humans focus solely on fixing. His deeper fear is that these capabilities will trickle into small, offline, guardrail-free local models, democratizing exploit generation in a way that creates systemic risk far beyond what any centralized tool with access controls can contain.
Onit Security: Decision-based Exposure Management, an AI-native Approach Eliminating Vulnerability Backlogs at Enterprise Scale
Brightmind invested in Onit Security, founded by Ofer Amitai, Elad Ben Meir, and Tom Winter, with Amitai's firsthand experience watching a vulnerability backlog lead to the compromise of his prior company Portnox serving as the driving force behind an entirely new approach to exposure management. Traditional vulnerability management has been fragmented across siloed scanners and homegrown workarounds, consistently failing enterprises due to limited asset context, inconsistent prioritization, and the inability to act without unintended consequences. Onit's decision-based, AI-native platform unifies business context with risk signals across the enterprise, embedding operator feedback directly into the engine to ensure autonomous, context-aware remediation that closes gaps at machine speed. With adversaries achieving breakout times as short as 27 seconds using AI, Brightmind sees Onit as the foundational layer for autonomous vulnerability management while also delivering meaningful productivity gains for IT and engineering teams.
Onit Security: Decision-based Exposure Management, an AI-native Approach Eliminating Vulnerability Backlogs at Enterprise Scale
Brightmind invested in Onit Security, founded by Ofer Amitai, Elad Ben Meir, and Tom Winter, with Amitai's firsthand experience watching a vulnerability backlog lead to the compromise of his prior company Portnox serving as the driving force behind an entirely new approach to exposure management. Traditional vulnerability management has been fragmented across siloed scanners and homegrown workarounds, consistently failing enterprises due to limited asset context, inconsistent prioritization, and the inability to act without unintended consequences. Onit's decision-based, AI-native platform unifies business context with risk signals across the enterprise, embedding operator feedback directly into the engine to ensure autonomous, context-aware remediation that closes gaps at machine speed. With adversaries achieving breakout times as short as 27 seconds using AI, Brightmind sees Onit as the foundational layer for autonomous vulnerability management while also delivering meaningful productivity gains for IT and engineering teams.
